# CERT-FR warns of nine curl vulnerabilities

Published: 2026-09-02 · Severity: elevated · Sectors: technology
Canonical: https://vorant.io/reports/cdf94748-340a-50ed-8eae-462deb11b2d6/cert-fr-warns-of-nine-curl-vulnerabilities

> CERT-FR advisory lists nine curl CVEs affecting versions 7.44.0 through 8.22.0 that can compromise data confidentiality, integrity, and security policy enforcement.

CERT-FR (the French national CERT) published an advisory summarizing nine vulnerabilities in the curl library affecting versions from 7.44.0 up to but not including 8.22.0. The advisory does not specify detailed technical mechanisms for each flaw but categorizes the risks as impacting data confidentiality, data integrity, and security policy bypass. No exploitation in the wild is mentioned in this bulletin.

Given curl's ubiquity as an underlying library in countless applications, operating systems, and embedded devices, organizations should identify all instances of curl within their software supply chain and update to version 8.22.0 or later as recommended by the curl project's own security bulletins referenced in the advisory. No proof-of-concept or active exploitation details are provided, and the advisory functions as a routine patch notification rather than an urgent incident report.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1108

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cdf94748-340a-50ed-8eae-462deb11b2d6/cert-fr-warns-of-nine-curl-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
